Skip to content
Preprint

LLM-Assisted Detection and Repair of Hardware Security Vulnerabilities in Verilog Designs

Aug 2026 · 0 citations · 10 references
Computer Science

TL;DR

The results demonstrate the potential of LLMs to augment traditional hardware security analysis by providing automated, scalable assistance for identifying security vulnerabilities during the hardware design process.

Abstract

Hardware designs, like software, are susceptible to bugs that can introduce security vulnerabilities and create opportunities for malicious exploitation. Unlike software vulnerabilities, however, hardware flaws become permanently embedded in silicon after fabrication, making them difficult or impossible to patch. Many of these weaknesses are categorized under the Common Weakness Enumeration (CWE) framework and include improper access control, exposure of sensitive information, and unintended privilege escalation. To improve the detection of such vulnerabilities, we propose a methodology that leverages a Large Language Model (LLM) to identify potential hardware CWEs directly from hardware designs in Verilog. The proposed approach is evaluated iteratively on a dataset of single-module Verilog designs to assess its effectiveness in detecting hardware security weaknesses. Our results demonstrate the potential of LLMs to augment traditional hardware security analysis by providing automated, scalable assistance for identifying security vulnerabilities during the hardware design process.

View source

Similar papers

Preprint Aug 2026

Lessons from the Hardware Hacking Competitions: Verification Techniques, Findings, and Insights

A multi-strategy vulnerability analysis methodology is presented, combining simulation-based verification, formal verification, lint analysis, Large Language Model-assisted bug detection, and coverage-guided hybrid fuzzing to derive practical lessons for pre-silicon security verification.

Sudipta Paria, Aritra Dasgupta, Raghul Saravanan et al. · 0 citations
Conference Open access 2026

LLM-Powered Automated Attacks

The increasing integration of large language models (LLMs) into systems introduces new attack surfaces that extend beyond traditional software vulnerabilities. While LLMs are commonly protected by prompt-level security mechanisms, recent researches show that these controls can be bypassed through carefully crafted inpu...

Tamás Girászi, Natália Papp, Norbert Oláh et al. · 0 citations
Review Open access Aug 2026

Detecting Vulnerabilities in Embedded Systems via Taint Analysis: A Survey

This article describes and categorize embedded systems, highlights the challenges posed by embedded systems for taint analysis, examine state-of-the-art techniques, and categorize dozens of tools in this field.

Guo-Hao Wu, Hong-Liang Liang, Lu-Ming Yin et al. · 0 citations
Open access Aug 2026

Static Code Analysis Framework for Automated Security Vulnerability Detection

Experimental results show that AST-based structural features substantially improve recall compared with the TF-IDF baseline, while the combined TF-IDF and AST representation maintains this improved performance.

Vani Pasupula, M. N. V. Manikanth, Nagaraju Vassey · 0 citations
#artificial intelligence Preprint Sep 2026

Beyond Static Guarantees: Measuring the Static-Pass Dynamic-Fail Gap in Security-Sensitive and LLM-Generated Python Code

Advances in large language models (LLMs) fuel the quest for scalable methods to assess the security of generated and security-sensitive software. Static analysis is widely adopted as a scalable, reproducible, and inexpensive security gate, but cannot directly observe runtime exploit behaviour. Vulnerabilities dependent...

Jessica Pourleyli, Maitreyee Das Urmi, Glaucia Melo · 0 citations
Review Oct 2026

Security Is More Than a Library Call: How Security Features Live in Code

Implementing security features---functionalities that protect sensitive data or prevent malicious actions by attackers---is important for ensuring the security and integrity of software systems. Correctly implementing access control, cryptography, or other security features is challenging as they require substantial do...

Kevin Hermann, Sven Peldszus, Thorsten Berger · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.